Yeqifu Warehouse Improper Access Control Vulnerability in Customer Management Endpoint

Vulnerability

A vulnerability exists in Yeqifu Warehouse versions up to commit aaf29962ba407d22d991781de28796ee7b4670e4, specifically within the Customer Endpoint. The issue arises in the CustomerController.java file, affecting the addCustomer, updateCustomer, and deleteCustomer functions. This vulnerability allows logged-in users to manipulate core business data by adding, updating, or deleting customer information without proper authorization. As a result, it could lead to unauthorized changes, fraudulent records, and potential disruptions in business operations. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for unauthorized access control, enabling logged-in users to alter or delete customer, provider, and goods data. This could result in significant integrity loss, creation of fraudulent records, and disruption of normal business operations.

Reproduction

To reproduce this vulnerability, log into the application and send a request to the customer management endpoints (addCustomer, updateCustomer, or deleteCustomer) without the necessary permissions. The absence of access control will allow the operation to be performed successfully, demonstrating the vulnerability.

Remediation

It is recommended to implement proper role-based access controls for the affected endpoints, ensuring that only authorized users can perform add, update, or delete actions. Validation of ownership should be included where applicable.

Added: Feb 20, 2026, 7:04 PM
Updated: Feb 20, 2026, 7:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
3.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.